Trojan

Trojan:MSIL/FormBook.EYC!MTB malicious file

Malware Removal

The Trojan:MSIL/FormBook.EYC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/FormBook.EYC!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Azorult malware family
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Trojan:MSIL/FormBook.EYC!MTB?


File Info:

name: 085945894359889FC316.mlw
path: /opt/CAPEv2/storage/binaries/9c17b08702418e52671e7a7d48db8375fd7a29bcb5654b4d54354efb7eef041d
crc32: 9C53161A
md5: 085945894359889fc3168c9ead4ec36d
sha1: 6d8884713b2fef8b04f34b42cd6f1018d6097c47
sha256: 9c17b08702418e52671e7a7d48db8375fd7a29bcb5654b4d54354efb7eef041d
sha512: 2e0598b8f9c694ceecfaccbe17f3d3d20b7ad4fc0ea0bf742bd311f9955c1554e81110997a1eda3593d87e69a2511a8b17e3bdaaec5897eb9ba8340486a9f12e
ssdeep: 12288:Too/oh781DHDvP65IN4WhKUof+Pq5mx0/qCICqZfTziXYZWqj8242zXpX34:l/KI1DHD365rWEUFPPx0i8qhiXYb9Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B915F150B2B41F62EBBC83F56506229807F1329BB46ED2645CC7A4F766B5F052A40F3B
sha3_384: 019e8aea7ec378f587c3bd0488e547f55007556a87b232be3bc691152a27b22830d286d5d4ce14250327729a4659fc8a
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-15 04:44:23

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: AIS_SIMULATION
FileVersion: 1.0.0.0
InternalName: IEnumSTORECATEG.exe
LegalCopyright: Copyright © 2014
LegalTrademarks:
OriginalFilename: IEnumSTORECATEG.exe
ProductName: AIS_SIMULATION
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/FormBook.EYC!MTB also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.DOTHETUK.4!c
tehtrisGeneric.Malware
DrWebTrojan.PackedNET.1449
MicroWorld-eScanTrojan.GenericKD.50641736
CAT-QuickHealTrojan.MSIL
ALYacTrojan.GenericKD.50641736
CylanceUnsafe
VIPRETrojan.GenericKD.50641736
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:MSIL/FormBook.bde178b2
K7GWRiskware ( 00584baa1 )
CyrenW32/MSIL_Agent.DNR.gen!Eldorado
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AFTF
TrendMicro-HouseCallTrojanSpy.Win32.AZORULT.YXCGOZ
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.DOTHETUK.gen
BitDefenderTrojan.GenericKD.50641736
NANO-AntivirusTrojan.Win32.DOTHETUK.jqdjhz
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Dothetuk.Eyj
Ad-AwareTrojan.GenericKD.50641736
EmsisoftTrojan.GenericKD.50641736 (B)
ComodoMalware@#s2lmegx7fj02
ZillyaTrojan.Kryptik.Win32.3832484
TrendMicroTrojanSpy.Win32.AZORULT.YXCGOZ
McAfee-GW-EditionRDN/AZORult
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
FireEyeTrojan.GenericKD.50641736
SophosMal/Generic-S + Troj/LokiBot-MH
IkarusTrojan.MSIL.Crypt
GDataTrojan.GenericKD.50641736
AviraTR/AD.MoksSteal.tfcge
Antiy-AVLTrojan/Generic.ASMalwS.8203
KingsoftWin32.Troj.Generic.jm.(kcloud)
ArcabitTrojan.Generic.D304BB48
MicrosoftTrojan:MSIL/FormBook.EYC!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Injection.C5207164
McAfeeRDN/AZORult
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.PNG.Generic
APEXMalicious
RisingStealer.Azorult!8.11176 (CLOUD)
YandexTrojan.DOTHETUK!WIYZuALEF6s
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FVTU!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/FormBook.EYC!MTB?

Trojan:MSIL/FormBook.EYC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment